CISM Exam Prep Questions and Answers
(Latest Update 2024)
Information security governance is primarily driven by: -
Correct Answer ✅ Business strategy
Who should drive the risk analysis for an organization? -
Correct Answer ✅ the Security Manager
Who should be responsible for enforcing access rights to
application data? - Correct Answer ✅ Security
administrators
The MOST important component of a privacy policy is: -
Correct Answer ✅ notifications
Investment in security technology and processes should be
based on: - Correct Answer ✅ clear alignment with the
goals and objectives of the organization
Define information security governance - Correct Answer ✅
1. A set of policies and procedures that establishes a
framework of information security strategies
,CISM Exam Prep Questions and Answers
(Latest Update 2024)
2. A practice area that ensures efficient utilization of
information resources
The main purpose of information security governance -
Correct Answer ✅ to ensure the safety of information
including its Confidentiality, Integrity and Availability.
Information security governance protects information from
loss, misuse, unauthorized usage, and destruction during its
life cycle or the time it is being used in an organization.
Benefits of information security governance - Correct
Answer ✅ - accountability for protecting information during
important business activities
- reduction of the impact of security incidents
- reduction in risks to tolerable limits
- protection from civil and legal liabilities
- enhancement of trust in customer relationships
- assurance of policy compliance
- protection of company reputation
, CISM Exam Prep Questions and Answers
(Latest Update 2024)
In order to be effective, information security governance
needs to provide 6 basic outcomes: - Correct Answer ✅ -
strategic alignment
- value delivery
- risk management
- performance measurement
- resource management
- integration
Should information security investments be optimized or
minimized? - Correct Answer ✅ Optimized so that they
support business objectives.
Primary goals of resource management: - Correct Answer
✅ - keeping a record of security practices and processes
- acquiring knowledge and making it accessible
- building a security architecture that identifies and uses
infrastructure resources properly
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller Allivia. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $12.49. You're not tied to anything after your purchase.